PT-2026-60856 · WordPress · Wordpress

CVE-2026-63030

·

Published

2026-07-17

·

Updated

2026-09-05

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WordPress versions 6.9.0 through 6.9.4 WordPress versions 7.0.0 through 7.0.1
Description A route confusion issue in the REST API batch endpoint, combined with a SQL injection in the WP Query class, allows a remote attacker to execute arbitrary code and gain unauthorized access to confidential information. The issue stems from the get items() function, where a desynchronization occurs between the permission check array, the allowed endpoints list, and the execution array. Additionally, the WP Query class fails to properly protect the SQL query structure when processing the author not in variable.
Recommendations Update WordPress versions 6.9.x to 6.9.5. Update WordPress versions 7.0.x to 7.0.2.

Exploit

Fix

DoS

RCE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10241
BDU:2026-10242
BIT-WORDPRESS-2026-63030
BIT-WORDPRESS-MULTISITE-2026-63030
CVE-2026-63030

Affected Products

Wordpress